IT Security, Director I (Hybrid)

American Medical Association

Chicago (IL)

Hybrid

USD 146,000 - 198,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

The American Medical Association (AMA) is seeking an IT Security Director I for a hybrid role in Chicago. Lead strategy, design, and operation of technical security controls across the organization, building strong relationships with IT and business teams.

This exempt position oversees security risk, regulatory compliance, incident response, and governance, driving security programs while enabling secure technology and data protection.

Qualifications

  • Minimum 10+ years engineering/design experience with security platforms.
  • Minimum 5 years conducting infrastructure and application project design reviews.
  • Bachelor's Degree in Computer Science or related discipline; professional certifications preferred.
  • Strong communication, integrity, and business acumen are required.

Responsibilities

  • Research, design, evaluate, and test security and regulatory compliance of AMA applications, systems, and networks.
  • Lead security strategy, governance, and risk management across IT and business units.
  • Manage security incidents, investigations, and reporting to senior leadership.
  • Mentor security and infrastructure staff and ensure alignment with enterprise standards.

Skills

Security leadership
Communication skills
Threat prevention techniques
Project management
Stakeholder collaboration

Education

Bachelor's degree in Computer Science or related discipline
Master's degree in Computer Science or related discipline

Tools

Qualys
Tenable
Wiz

Job description

IT Security, Director I (Hybrid)
Chicago, IL

The American Medical Association (AMA) is the nation's largest professional Association of physicians and a non-profit organization. We are a unifying voice and powerful ally for America's physicians, the patients they care for, and the promise of a healthier nation. To be part of the AMA is to be part of our Mission to promote the art and science of medicine and the betterment of public health.

At AMA, our mission to improve the health of the nation starts with our people. We foster an inclusive, people-first culture where every employee is empowered to perform at their best. Together, we advance meaningful change in health care and the communities we serve.

We encourage and support professional development for our employees, and we are dedicated to social responsibility. We invite you to learn more about us and we look forward to getting to know you.

We have an opportunity at our corporate offices in Chicago for an IT Security, Director I (Hybrid) on our Information Technology team. This is a hybrid position reporting into our Chicago, IL office, requiring 3 days a week in the office.

This role is responsible
for providing subject matter expertise on the strategy, research, design,
implementation, and operation of technical and process security controls. Develops strong relationships across the AMA's IT department and with business unit teams; serves as a trusted advisor to assess security risk in technology
selection with appropriate balance that supports business outcomes. Responsibilities
include data security, collaboration with the security operations team, and
maintaining the broad suite of information security infrastructure, and all
associated contracting, policy, and regulatory compliance implications. Maintain cybersecurity and related regulatory expertise to research,
prepare, and maintain strategic roadmaps incorporated into the Information
Security Program. Lead or assist with
security incidents and compliance investigations and produce timely and clear
reporting to both technical and senior business leader audiences. Serves as
primary backup for the Director IT Security.

RESPONSIBILITIES:
System/Network/Application Security Strategy
  • Research, design,
    evaluate, and test the security and regulatory compliance of AMA applications,
    systems, and networks to ensure the operational effectiveness of technical controls implemented by the
    organization; purpose-built security tools such as data loss prevention,
    logging and event management, enterprise encryption systems and also security
    controls embedded in enterprise systems and applications such as authentication
    and access controls
  • Responsible for the effective use of AMA cybersecurity systems including enhancements, upgrades, and lifecycle management through
    relationships with product and service vendors
  • Responsible for
    the technical integration of security components within the AMA's environment
    to optimize the value and control benefits including ease of use, effectiveness, and breadth of coverage
Technology and Regulatory Risk Management
  • Assess technical risks in the AMA's environment both pre and post-production through the AMA's Software Development
    Lifecycle (SDLC) and Change & Release
  • Management Boards; propose
    information security strategy and program improvements, communicate identified
    risks and recommend solutions
  • Manage the research, appropriate response, and remediation of malicious and inappropriate activity; ensure consistency of the risk
    assessment approach across the organization
  • Prepare policy updates;
    research and recommend short and long-term improvements to maintain strong security posture relative to enterprise architecture standards, data integration/data access, cloud
    strategy, and AI implementations
  • Collaborate in
    developing, recommending and implementing the AMA's information security
    policies, and governance frameworks; this includes aligning security initiatives with business goals and ensuring compliance with
    industry standards and regulations
  • Ensures compliance with relevant laws, regulations, and frameworks, such as PCI, GDPR, NIST, or ISO standards, and manages security audits and assessments
  • Co-manage new software, data, and service provider products and contract reviews
  • Responsible for staying current on threats and best practices in the field of cybersecurity
Service Delivery
  • Manage continuous process improvement to identify technical or process enhancements in the delivery of IT
    Security services to increase service quality
  • Prioritize improvements on a cost/benefit basis, communicating opportunities to management.
  • Serve as an escalation point in the fulfillment of IT Security service requests
Project Management
  • Manage IT
    Security-led projects following the AMA's applicable project governance
    processes, including Software Development Life Cycle; ensure successful project outcomes, such as completing projects within time and
    budget tolerances
  • Mentor security and infrastructure team members, including analysts, engineers, and managers,
    related to information security strategies and threat prevention techniques.

May include other responsibilities as assigned

REQUIREMENTS:
  1. Minimum 10+ years engineering/design experience with a mix of the following security platforms is required: network and application-layer firewalls
    and secure network design; infrastructure and application-layer vulnerability
    management, security information and event management (SIEM); Security,
    Orchestration, Automation and Response (SOAR), data loss prevention (DLP);
    enterprise encryption solutions for database, file systems and data in motion;
    Internet/Web Gateway; end point security controls (such as anti-virus, anti-malware XDR, host-based firewall, and full disk encryption
    solutions); and intrusion detection and prevention systems. Knowledge of Attack and Penetration
    methodologies, tools, and techniques
  2. Minimum 5 years
    conducting infrastructure and application project design reviews
    Engineering/design experience with a mix of the following infrastructure
    technologies is required: Microsoft/Azure (Azure AD, ADFS, M365, Sharepoint 2019, Windows Server2019-2022, Windows 10-11); Red
    Hat Linux, VMware, AWS EC2, S3, IAM
  3. Demonstrated industry leadership capabilities, and recognized as a subject expert in the information
    security field.
  4. Knowledge of
    security scanning and analyzing tools; Commercial Application and
    Infrastructure/Operating System and Opensource Vulnerability scanning/management, and
    freeware/commercial Wireshark, NMAP, Burp Suite, Nikto, Qualys, Tenable, Snyk,
    Wiz
  5. Polished verbal and written communication, interpersonal, analytical, and organizational skills, attention to detail, and a high
    level of integrity are required
  6. Strong business acumen. Ability to understand the organization's various business functions and their objectives
  7. Experience with project management and software development lifecycle methodologies preferred.
  8. Professional IT Security and IT Audit certifications such as CISSP,CISM, CEH, CISA, and/or
    technical certifications preferred
  9. Experience with IT Infrastructure Library (ITIL) - particularly incident, change, release, and/or problem management preferred
  10. Experience with IT
    security standards, such as CIS Top 20, ISO 27001, NIST CSF, NIST 800-53,
    HITRUST, MITRE, OWASP,CWE/SANS Top 25 Programming Errors, and attestation reports such as SOC 1/2/3 and technology risk management methodologies, such as
    NIST 800-30 preferred.
  11. Experience with compliance standards such as PaymentCard Industry (PCI),Sarbanes Oxley (SOX) and Health Insurance Portability
    Accountability Act (HIPAA) preferred
  12. Bachelor's Degree in Computer Science or related discipline strongly preferred. Master's Degree in Computer Science or related discipline
    a plus
Additional Technical Background Experience with:
  1. Cloud-based security tools (CloudTrail, WAF, Security Center, etc.)
  2. Source code management tools (GitHub, BitBucket, etc.)
  3. Code scanning tools (Dynamic, Static and Opensource)
  4. Vulnerability Management solutions(Qualys, Tenable, Wiz)
Knowledge of:
  1. User authentication such as Zero Trust concepts, SAML and OAuth-based SSO architectures and IDP
    integrations, MFA, Virtual Private Networks (VPNs), TLS, PAM, corporate wifi,
    device identity, 802.1x port-based authentication, server identification,
    authentication of web applications, S/MIME Email Signing, is desirable
  2. Programming languages (.Net, Java, JavaScript, Angular, Drupal, Python, etc.) Web services, API, REST, RPC Infrastructure as Code (CloudFormation, Terraform) preferred
    Administration of
    Azure suite, including; Azure Active Directory, Conditional Access, Intune,
    Mobile Application Management, Microsoft Cloud App Security, and/or advanced
    Azure security services like Azure Security Center, Advanced DDoS Protection, Azure Firewall, and Azure WAF
  3. Administration of AWS security services and related best practices: GuardDuty, Cognito, Inspector,
    Detective and advocate AWS Identity & Access Management (IAM)
  4. Operating systems: Windows, Mac, Linux, WVD, VDI, and Jump Boxes/Bastion Servers
  5. Network routing and communication frameworks, protocols, and technologies such as OSI, TCP/IP
    v4 & v6, RIP, OSPF, VPN, HTTPS, TLS, and SSH is required.
  6. Working knowledge of SQL, LDAP, and/or regex is a plus.

The American Medical Association is located at 330 N. Wabash Avenue, Chicago, IL 60611 and is convenient to all public transportation in Chicago.

This role is an exempt position, and the salary range for this position is $146,384 - $197,728. This is the lowest to highest salary we believe we would pay for this role at the time of this posting. An employee's pay within the salary range will be determined by a variety of factors including but not limited to business consideration and geographical location, as well as candidate qualifications, such as skills, education, and experience. Employees are also eligible to participate in an incentive plan. To learn more about the American Medical Association's benefits offerings, please click here.

We are an equal opportunity employer, committed to diversity in our workforce. All qualified applicants will receive consideration for employment. As an EOE/AA employer, the American Medical Association will not discriminate in its employment practices due to an applicant's race, color, religion, sex, age, national origin, sexual orientation, gender identity and veteran or disability status.

THE AMA IS COMMITTED TO IMPROVING THE HEALTH OF THE NATION

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Software Engineer, Platform (Hybrid)
Sr. Software Engineer, Platform (Hybrid)

American Medical Association • Chicago (IL)

Hybrid
USD 116,000 - 151,000
Software Engineer II (Hybrid)
Software Engineer II (Hybrid)

American Medical Association • Chicago (IL)

Hybrid
USD 99,000 - 129,000
Data Engineer II (Hybrid)
Data Engineer II (Hybrid)

American Medical Association • Chicago (IL)

Hybrid
USD 85,000 - 113,000
Lead Policy Analyst (Hybrid)
Lead Policy Analyst (Hybrid)

American Medical Association • Chicago (IL)

Hybrid
USD 105,000 - 139,000
Incentive plan
Vice President, Business Development (Hybrid)
Vice President, Business Development (Hybrid)

American Medical Association • Chicago (IL)

Hybrid
USD 239,000 - 323,000
Director I, Content (Hybrid)
Director I, Content (Hybrid)

American Medical Association • Chicago (IL)

Hybrid
USD 129,000 - 174,000
Senior Manager, Business Unit Systems (Hybrid)
Senior Manager, Business Unit Systems (Hybrid)

American Medical Association • Chicago (IL)

Hybrid
USD 119,000 - 158,000
Program Specialist II (Hybrid)
Program Specialist II (Hybrid)

American Medical Association • Washington

Hybrid
USD 79,000 - 105,000
Sr. Manager Learning Design
Sr. Manager Learning Design

American Medical Association • Chicago (IL)

Hybrid
USD 105,000 - 139,000
Hybrid IT Security Director
Hybrid IT Security Director

American Medical Association • Chicago (IL)

Hybrid
USD 146,000 - 198,000